Skip to content

OverridesBuiltInTool is ignored for store_memory / vote_memory; calls run the built-in memory executor #5063

Description

@toliaqat

Describe the bug

An SDK host can register an external tool named store_memory (or vote_memory) with overridesBuiltInTool: true. The runtime plans the override and removes the built-in from the tool list the model sees. However, when the model calls the tool, the runtime runs the built-in memory executor instead of the host's tool, including the built-in memory permission flow. The host's handler is never invoked. No error or warning is raised.

Overrides of other built-ins, such as read_file, work as expected.

Root cause

  • Planning (session/tool_initialization.rs, plan_eager_tool_initialization): memory tools are added to the built-in list there, so session_local_external_tool_overrides_json correctly marks store_memory as overridden. The model is offered the host's definition.
  • Dispatch (tools/session_tool_invoker.rs, external_override_definition): an override is honoured only when is_runtime_builtin is true. That check uses registry::get_builtin_tool_descriptor(name) plus a few special cases (rg, lsp, task, shell tools).
  • store_memory and vote_memory are materialized by the tool catalog and aren't returned by get_builtin_tool_descriptor. See registry::is_catalog_materialized_builtin_tool_name, which lists them explicitly.
  • external_override_definition therefore returns Ok(None) and execute_tool_result falls through to the built-in memory handler.
  • Planning and dispatch disagree about which names are overridable built-ins. Any other catalog-materialized name not otherwise special-cased (lexical_code_search, semantic_code_search, canvas tools) may be affected the same way.

Affected version

1.0.13

Steps to reproduce the behavior

  1. Using the .NET SDK (reported on 1.0.13), create a session with memory enabled.
  2. Register an external tool named store_memory with OverridesBuiltInTool = true and a handler that logs its invocation. Optionally register read_file the same way as a control.
  3. Prompt the agent to remember a fact, for example "Remember that our build command is make ci."
  4. Observe that the host store_memory handler is never called and the built-in memory permission request is raised instead. A read_file override in the same session is invoked normally.

Expected behavior

When a host registers store_memory / vote_memory with overridesBuiltInTool: true:

  • calls go to the host's external tool handler, and
  • the built-in memory executor and its permission prompt are not used.

More generally, the set of names accepted as overridable at planning time should match the set honoured at dispatch.

Additional context

  • SDK: GitHub Copilot SDK for .NET 1.0.13 (reporter). Root cause verified against current main.
  • Workaround: disable built-in memory (Memory = new MemoryConfiguration { Enabled = false }) and register memory tools under distinct names.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:context-memoryContext window, memory, compaction, checkpoints, and instruction loadingarea:toolsBuilt-in tools: file editing, shell, search, LSP, git, and tool call behavior

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions